Skip to main content
AI RegulationPolicy MilestoneAug 2, 2026, 6:17 PM· 3 min read· #1 of 2 in ai

Illinois Governor Signs Landmark AI Act With First-in-Nation Mandatory Third-Party Audit for Frontier Models

Illinois has enacted the Artificial Intelligence Safety Measures Act, becoming the first U.S. state to mandate annual independent third-party audits for developers of massive frontier AI models. The legislation joins similar frameworks in California and New York to solidify a de facto national standard for AI safety and transparency.

By Logan Price

State Regulators 40%Legal & Compliance Experts 35%Consumer Advocates 25%
State Regulators
Argue that states must lead on AI safety to protect the public amid federal inaction.
Legal & Compliance Experts
Focus on the operational impact of the law and the emergence of a de facto national standard.
Consumer Advocates
Praise the transparency measures but criticize the inability of individuals to sue for AI-driven harms.

Why this matters

By mandating independent safety audits for the world's most powerful AI systems, Illinois is closing a major loophole in tech oversight. Because the law applies to any major developer doing business in the state, it effectively forces national compliance, giving the public unprecedented visibility into the risks of frontier models.

Key points

  • Illinois is the first U.S. state to mandate independent third-party safety audits for large AI developers.
  • The law applies only to frontier models trained with massive computing power by companies earning over $500 million annually.
  • Developers must report critical safety incidents to state emergency agencies within 24 to 72 hours.
  • The legislation relies on the state Attorney General for enforcement, with fines reaching up to $3 million for repeat offenses.
  • Combined with similar laws in California and New York, the act helps establish a de facto national standard for AI safety.
$500 million
Annual revenue threshold for developers
10²⁶ FLOPS
Compute threshold defining a frontier model
24 to 72 hours
Window to report critical safety incidents
$3 million
Maximum fine for repeat violations

Illinois Governor JB Pritzker has signed the Artificial Intelligence Safety Measures Act (SB 315) into law, establishing one of the most stringent regulatory frameworks for advanced AI in the United States. The legislation makes Illinois the first state to require mandatory, independent third-party audits for developers of massive "frontier" AI models. [1][3][1][3]

The new law targets the largest and most resource-intensive artificial intelligence systems—specifically those trained using more than 10²⁶ floating-point operations by companies generating over $500 million in annual revenue. [6][7] By setting these high thresholds, the legislation focuses squarely on industry giants like OpenAI, Google, Anthropic, and Meta, rather than stifling smaller startups or open-source researchers. [4][6][4][6]

The centerpiece of the legislation is its unprecedented audit mandate. Beginning in 2028, large frontier developers must hire independent third-party evaluators to annually assess their compliance with safety protocols and internal risk controls. [6][8] Crucially, the law stipulates strict independence criteria, ensuring that auditors have no financial conflicts of interest with the tech companies they are evaluating. [8][6][7]

The new law targets only the largest frontier AI developers, setting strict thresholds for compliance.
The new law targets only the largest frontier AI developers, setting strict thresholds for compliance.

Beyond audits, the law requires developers to publish comprehensive safety frameworks detailing how they identify and mitigate "catastrophic risks"—such as the potential for an AI model to assist in creating biological weapons or executing large-scale cyberattacks. [1][7] Companies must also report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours, or just 24 hours if the risk is deemed imminent. [5][6][1][5][6]

Enforcement of the new regulations falls exclusively to the Illinois Attorney General, who can levy civil penalties of up to $1 million for a first violation and $3 million for subsequent offenses. [3][8] The legislation does not include a private right of action, meaning individual citizens cannot sue AI companies directly under this specific law for algorithmic harms, a compromise that helped secure broad bipartisan support. [4][5][3][4][5][7]

During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock. He emphasized that the state is choosing a path of "innovation with security," ensuring that the costs and detriments of unchecked technological growth are not pushed onto ordinary citizens. [1][3] Pritzker openly criticized Congress for remaining captive to special interests and failing to pass a cohesive national framework. [1][2][1][2][3]

During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock.

Illinois now joins California and New York, which passed similar frontier AI transparency laws in late 2025. [1][2] Legal experts note that because these three states collectively account for roughly 40% of the U.S. AI market, their combined regulations effectively create a de facto national standard. [1][6] It is logistically unfeasible for major tech companies to build separate AI models for different states, meaning the Illinois audit requirement will likely become standard industry practice nationwide. [6][8][1][2][6][7]

Together with California and New York, Illinois helps form a regulatory bloc that effectively dictates national AI standards.
Together with California and New York, Illinois helps form a regulatory bloc that effectively dictates national AI standards.

The tech industry's reaction has been surprisingly cooperative. Major players like OpenAI have publicly endorsed the Illinois framework, describing it as one of the strongest safety laws in the country. [6] This support reflects a growing consensus among leading labs that clear, predictable state regulations are preferable to a chaotic patchwork of conflicting local ordinances or the looming threat of more draconian federal interventions. [6][7][6]

The transparency and reporting provisions of the Artificial Intelligence Safety Measures Act will officially take effect on January 1, 2027, giving developers a brief runway to align their internal compliance programs. [6][8] The more rigorous third-party audit requirements will follow a year later in 2028, marking a critical transition from an era of self-reported AI safety to one of verified, independent oversight. [7][8][6][7]

How we got here

  1. Late 2025

    California and New York pass the nation's first major frontier AI transparency laws.

  2. May 2026

    The Illinois General Assembly passes the Artificial Intelligence Safety Measures Act (SB 315) with bipartisan support.

  3. July 2026

    Governor JB Pritzker signs the bill into law, adding the first-in-the-nation third-party audit requirement.

  4. January 2027

    Transparency, reporting, and safety framework requirements officially take effect.

  5. January 2028

    Mandatory independent third-party audits begin for all qualifying large frontier developers.

Viewpoints in depth

State Regulators & Lawmakers

State governments are stepping in to fill the regulatory void left by federal inaction.

Lawmakers in Illinois, California, and New York argue that waiting for Congress to pass comprehensive AI legislation is no longer a viable strategy. By implementing strict transparency and audit requirements at the state level, they aim to establish a baseline of accountability before frontier models become deeply entrenched in critical infrastructure. They view these laws not as anti-innovation, but as necessary guardrails that protect the public from catastrophic risks while providing clear rules of the road for developers.

Frontier AI Developers

Leading AI companies are embracing state-level frameworks to ensure regulatory predictability.

Major developers like OpenAI and Anthropic have largely supported these state-level transparency bills. For the industry's biggest players, complying with mandatory audits and safety frameworks is a manageable cost of doing business that helps build public trust. Furthermore, a unified bloc of state laws is vastly preferable to a fragmented landscape of conflicting local rules. By endorsing bills like the Illinois Act, these companies can help shape the regulatory environment and avoid more restrictive measures that might stifle core research.

Consumer Rights Advocates

While praising the safety audits, advocates warn that the lack of a private right of action limits direct accountability.

Consumer protection groups celebrate the mandatory third-party audits as a historic win for algorithmic transparency. However, they express concern over the law's enforcement mechanism, which relies entirely on the state Attorney General. Because the legislation explicitly excludes a private right of action, individuals who are harmed by an AI system—such as through algorithmic discrimination in hiring or healthcare—cannot use this specific law to sue the developers directly. Advocates argue this leaves a critical gap in compensating victims of AI-driven harm.

What we don't know

  • How the independent third-party auditing industry will scale to meet the complex technical demands of evaluating frontier AI models by 2028.
  • Whether the federal government will eventually preempt these state-level frameworks with a unified national AI law.
  • Exactly how 'catastrophic risk' thresholds will be legally defined and measured in practice during the auditing process.

Key terms

Frontier Model
A highly capable foundation AI model trained using massive amounts of computing power, typically exceeding 10²⁶ floating-point operations.
Third-Party Audit
An independent evaluation conducted by an external organization to verify that a company is complying with safety and regulatory standards.
Private Right of Action
A legal provision that allows ordinary citizens to file lawsuits directly against a company for violating a specific law.
Catastrophic Risk
The potential for an AI system to cause large-scale harm, such as assisting in the creation of biological weapons or facilitating severe cyberattacks.

Frequently asked

Does this law apply to all AI startups?

No. The law specifically targets 'large frontier developers' with over $500 million in annual revenue that train models using massive computing power. Small startups and open-source researchers are generally exempt.

Can I sue an AI company under this new law?

No. The legislation does not include a private right of action. Only the Illinois Attorney General has the authority to enforce the law and levy fines against violators.

When do the new rules take effect?

The transparency and safety reporting requirements begin on January 1, 2027. The mandatory third-party audits will start a year later, on January 1, 2028.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

State Regulators 40%Legal & Compliance Experts 35%Consumer Advocates 25%
  1. [1]Capitol News IllinoisState Regulators

    Pritzker signs landmark AI regulation bill that aims to mitigate risks

    Read on Capitol News Illinois
  2. [2]The Washington PostState Regulators

    Gov. JB Pritzker has signed a new artificial intelligence law in Illinois

    Read on The Washington Post
  3. [3]JURISTState Regulators

    Illinois Governor JB Pritzker signs landmark artificial intelligence bill

    Read on JURIST
  4. [4]The Legal ExaminerConsumer Advocates

    What Does the Illinois Artificial Intelligence Safety Measures Act Do?

    Read on The Legal Examiner
  5. [5]Transparency CoalitionConsumer Advocates

    Illinois Gov. Pritzker signs nation's 'most protective' AI Safety Measures Act into law

    Read on Transparency Coalition
  6. [6]SkaddenLegal & Compliance Experts

    Illinois Imposes Transparency and Safety Obligations on Frontier AI Systems

    Read on Skadden
  7. [7]Latham & WatkinsLegal & Compliance Experts

    Illinois' SB 315 is the first law in the US to mandate third-party audits for large AI developers

    Read on Latham & Watkins
Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.